CVE-2020-7595 (NVD)

2020-01-21

xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.

Products Ubuntu_linux, Debian_linux, Fedora, Clustered_data_ontap, H300e_firmware, H300s_firmware, H410c_firmware, H410s_firmware, H500e_firmware, H500s_firmware, H700e_firmware, H700s_firmware, Smi\-S_provider, Snapdrive, Steelstore_cloud_integrated_storage, Symantec_netbackup, Communications_cloud_native_core_network_function_cloud_native_environment, Enterprise_manager_base_platform, Enterprise_manager_ops_center, Mysql_workbench, Peoplesoft_enterprise_peopletools, Real_user_experience_insight, Sinema_remote_connect_server, Libxml2
Type Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
First patch - None (likely due to unavailable code)
Links https://www.oracle.com/security-alerts/cpujul2022.html
https://security.netapp.com/advisory/ntap-20200702-0005/
https://gitlab.gnome.org/GNOME/libxml2/commit/0e1a49c89076
https://cert-portal.siemens.com/productcert/pdf/ssa-292794.pdf
https://www.oracle.com/security-alerts/cpujul2020.html